Exposição de PostgreSQL

Databases
77
score de exposição
10.313
sites usam
0
em exploração
0
críticos
Análise Vexday

O PostgreSQL acumula 83 CVEs catalogadas, sem registros de exploração ativa no catálogo KEV da CISA e sem vulnerabilidades de severidade crítica no conjunto atual — taxa abaixo da média geral do catálogo, o que sugere um perfil de risco relativamente controlado em relação ao universo de vendors monitorados. O tipo de falha mais frequente é CWE-200, relacionada à exposição indevida de informações, padrão que merece atenção em configurações de acesso e controle de privilégios. O ponto de maior atenção imediata é CVE-2025-1094, que apresenta EPSS de 0,89, indicando alta probabilidade de exploração na prática — essa CVE deve ser tratada como prioridade mesmo na ausência de confirmação formal no KEV. Adicionalmente, 11 vulnerabilidades surgiram nos últimos 90 dias, sinalizando atividade recente na superfície de ataque que requer monitoramento contínuo.

CVEs

111 resultados
CVE-2017-12172PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runsEPSS 0.6%CVE-2026-6478MEDIUMPostgreSQL discloses MD5-hashed passwords via covert timing channelEPSS 0.6%CVE-2020-14350It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privilEPSS 0.5%CVE-2020-10733The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in theEPSS 0.5%CVE-2026-16239HIGHPostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary codeEPSS 0.5%CVE-2026-2007HIGHPostgreSQL pg_trgm heap buffer overflow writes pattern onto server memoryEPSS 0.5%CVE-2018-1053In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates filEPSS 0.5%CVE-2026-6479HIGHPostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionEPSS 0.5%CVE-2026-14662HIGHPostgreSQL tsvector and tsquery undersize allocations, via integer wraparoundEPSS 0.5%CVE-2026-6477HIGHPostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryEPSS 0.5%CVE-2019-10128A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not locEPSS 0.4%CVE-2026-14664HIGHPostgreSQL regexp heap buffer overflow executes arbitrary codeEPSS 0.4%CVE-2026-14670HIGHPostgreSQL plperl tied object heap buffer overflow executes arbitrary codeEPSS 0.4%CVE-2026-15742HIGHPostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparoundEPSS 0.4%CVE-2026-14676HIGHPostgreSQL pg_stat_statements heap buffer overflow executes arbitrary codeEPSS 0.4%CVE-2026-19385HIGHPostgreSQL pg_dump heap buffer overflow executes arbitrary codeEPSS 0.4%CVE-2025-8715HIGHPostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target serverEPSS 0.4%CVE-2026-14671HIGHPostgreSQL refint plan cache type confusion executes arbitrary codeEPSS 0.4%CVE-2026-14680HIGHPostgreSQL type confusion via "internal" argumentsEPSS 0.4%CVE-2026-14677HIGHPostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparoundEPSS 0.4%